GSEC Security Frameworks and CIS Controls Practice Question
A mid-sized healthcare provider has adopted the CIS Critical Security Controls and wants to measure the effectiveness of its security program over time. The CISO asks you to recommend a method that provides a quantifiable, repeatable score of how well the organization is implementing the CIS Controls. Which approach best meets this requirement?
⚠ Common exam trap
Test-takers frequently confuse technical metrics like vulnerability counts or MTTR with a structured, control-based maturity assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a CIS Controls Self Assessment Tool (CIS CSAT) using the CIS Controls Implementation Group criteria to generate a maturity score.
The CIS Controls Self Assessment Tool (CSAT) is designed specifically to measure an organization's implementation of the CIS Controls and produce a quantifiable maturity score. It aligns with Implementation Groups and enables repeatable tracking over time. Other options focus on narrow technical metrics that do not assess the breadth of the CIS Controls or provide a consistent program-level score.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy a vulnerability scanner across all subnets and track the total count of open vulnerabilities as the main indicator.
Why it's wrong here
Vulnerability scanning addresses only a subset of technical weaknesses and does not assess the full range of CIS Controls, such as data recovery, access management, or security awareness. The count of open vulnerabilities is not a stable or comprehensive metric for program effectiveness and cannot be used to measure implementation of the CIS Controls.
- ✗
Conduct a penetration test against the external perimeter and use the number of critical findings as the primary metric.
Why it's wrong here
A penetration test evaluates technical vulnerabilities at a point in time and does not measure implementation of the CIS Controls. The number of findings can fluctuate based on tester skill and scope, and it provides no structured view of control coverage. It fails to deliver a repeatable, control-based score that reflects overall security program maturity.
- ✓
Perform a CIS Controls Self Assessment Tool (CIS CSAT) using the CIS Controls Implementation Group criteria to generate a maturity score.
Why this is correct
CIS CSAT is the official self-assessment tool that maps an organization's implementation of the CIS Controls to Implementation Groups and produces a quantifiable maturity score. It allows repeatable measurements over time, directly addressing the CISO's need to track program effectiveness and demonstrate progress against the CIS Controls framework.
- ✗
Calculate the mean time to remediate (MTTR) security incidents and present that as the sole measure of control effectiveness.
Why it's wrong here
MTTR is an incident response metric and does not evaluate the implementation status of the CIS Controls. A low MTTR could coexist with poor preventive controls, and the metric ignores most control domains. It cannot provide a structured, repeatable score of CIS Controls implementation, making it unsuitable for the CISO's request.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.